PatchSiren cyber security CVE debrief
CVE-2026-94544 vercel CVE debrief
CVE-2026-94544 debrief: Next.js vulnerability allows Draft Mode content leakage through shared pending `use cache` fills, impacting sites with Cache Components or experimental.useCache enabled. This occurs when Draft Mode requests and regular requests overlap, causing the second request to receive the first request's fill. As a result, a regular request may receive unpublished content without authentication, while a Draft Mode request may receive published content instead of the draft. If the overlapping regular request prerenders a page, the unpublished content can be persisted into the generated page and served to later visitors until the page is revalidated. The vulnerability is
- Vendor
- vercel
- Product
- next
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders and administrators of sites using Next.js with Cache Components or experimental.useCache and serving Draft Mode previews should assess exposure and verify content leakage. This includes reviewing Draft Mode usage, verifying persisted pages for potential unpublished content, and considering upgrades to mitigate the vulnerability. Security teams and operators should prioritize verifying exposure and assessing the impact on their environments.
Why it matters
CVE-2026-94544 allows leakage of Draft Mode content into regular responses and persisted pages in Next.js, impacting sites with Cache Components or experimental.useCache enabled
- Unpublished content can be served to regular users without authentication
- Draft Mode requests may receive published content instead of draft content
- Persisted pages can be generated with unpublished content and served to later visitors
- Verification of exposure and content leakage is necessary
Technical summary
Pending `use cache` fills in Next.js can leak Draft Mode content into regular responses and persisted pages when overlapping requests occur. This happens because cached functions are shared across requests without distinguishing between Draft Mode and regular requests. As a result, a regular request may receive unpublished content, while a Draft Mode request may receive published content. The vulnerability can lead to persisted pages being generated with unpublished content and served to later visitors until the page is revalidated.
Defensive priority
Defenders should prioritize verifying exposure and assessing Draft Mode usage
Recommended defensive actions
- Verify if Cache Components or experimental.useCache is enabled and serving Draft Mode previews
- Assess exposure of Draft Mode usage and content
- Consider upgrading to version 16.3.8 or later
- Review and revalidate persisted pages for potential unpublished content
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from the source corpus indicates that sites using Next.js with Cache Components or experimental.useCache and serving Draft Mode previews are affected. The source item detailing the vulnerability confirms that overlapping requests can lead to content leakage. To verify exposure, defenders should assess Draft Mode usage and content. The official CVE Program record and NIST NVD detail page provide additional context on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94544 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94544
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94544 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94544
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persist
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-3w37-wq28-93x7.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/security/advisories/GHSA-3w37-wq28-93x7
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/commit/bd9214f9a32854a011bf5fe58e481dffe1bbf598
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/releases/tag/v16.3.8
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.